Book Chapter10.1002/9781118851678.CH38
Writing Secure Code
Lester E. Nichols,M. E. Kabay,Timothy Braithwaite +2 more
- 12 Sep 2015
150
TL;DR: This document refers to numerous hardware and software products by their trade names as well as other companies and their products for informational purposes only.
read more
Abstract: Due to the nature of this material, this document refers to numerous hardware and software products by their trade names. References to other companies and their products are for informational purposes only, and all trademarks are the properties of their respective companies. It is not the intent of ProTech Professional Technical Services, Inc. to use any of these names generically C o u rs e O u tl in e Writing Secure Code
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
Citations
Integrating Security Concerns into Software Development
Sabah Al-Fedaghi,Fajer Al-Kanderi +1 more
- 01 Jan 2013
TL;DR: A flow-based diagrammatic representation that includes security concerns in the dynamic behavior of security attacks is introduced, and the advantages of the methodology are demonstrated through contrasting it with a statechart-based study case.
5
Integrating Security into Computer Science Curriculum
Onyeka Ezenwoye
- 01 Oct 2019
TL;DR: This work demonstrates that security-related content can be added to the curriculum in a comprehensive manner and should not require significant re-tooling of existing faculty to gain specialized knowledge in software security.
5
•Posted Content
Entwicklung eines Reputationssystems für cyber-physikalische Systeme am Beispiel des inHMotion Forschungsprojektes
TL;DR: This work looks at the usage of reputation systems in the field of CPS and whether they could be used to assert the trustworthyness of communication partners and the concept of a meta reputation system, which combines different reputation systems and verification systems can achieve promising results in a simple simulation.
4
Information security risk management and incompatible parts of organization
TL;DR: A new model to recognize the degrees of incompatibility among independent divisions of an organization with dependent security assets is presented, based on positive and negative interdependencies in the parts, which provides how the organization can decrease the security risks through non-cooperation rather than cooperation.
4
Model-Driven Security With Modularity and Reusability For Engineering Secure Software Systems
Phu H. Nguyen
- 10 Sep 2015
TL;DR: This PhD work addresses three of the main open issues in the current state of the art of MDS research by proposing a highly modular, reusable MDS solution based on a System of Security design Patterns (SoSPa) and reusable aspect models to tackle multiple security concerns systematically.
References
•Book
Applied Cryptography: Protocols, Algorithms, and Source Code in C
Bruce Schneier,Phil Sutherland +1 more
- 10 Nov 1993
TL;DR: This document describes the construction of protocols and their use in the real world, as well as some examples of protocols used in the virtual world.
4K
•Book
Reversing: Secrets of Reverse Engineering
Eldad Eilam
- 01 Jan 2005
TL;DR: This book provides readers with practical, in-depth techniques for software reverse engineering, including computer internals, operating systems, and assembly language.
411
•Book
Network and Internetwork Security: Principles and Practice
William Stallings
- 01 Nov 1994
TL;DR: Each basic building block of network security is covered, including conventional and public-key cryptography, authentication, and digital signatures, as are methods for countering hackers and other intruders and viruses.
Classification of Security Threats in Information Systems
TL;DR: A hybrid model for information system security threat classification is defined in order to propose a classification architecture that supports all threat classification principles and helps organizations implement their information security strategies.
278
•Posted Content
DAG-Based Attack and Defense Modeling: Don't Miss the Forest for the Attack Trees
TL;DR: In this article, the authors present the current state of the art on attack and defense modeling approaches that are based on directed acyclic graphs (DAGs), allowing for a hierarchical decomposition of complex scenarios into simple, easily understandable and quantifiable actions.
226